Human Risk Management

Build better security habits. Test them continuously.

Vectra Human Risk Management combines phishing simulations and security awareness training to help users recognise social engineering, make safer decisions and report suspicious activity earlier. Choose the depth and flexibility of KnowBe4, or integrate awareness directly into Check Point Email Security.

SimulateTest realistic phishing and social-engineering scenarios in a controlled environment.
TrainGive users relevant security awareness content instead of treating training as an annual checkbox.
ReinforceUse feedback, targeted learning and repeat testing to turn mistakes into better habits.
MeasureTrack reporting, simulation outcomes, training completion and risk trends over time.
ImproveAdjust campaigns around the threats, teams and behaviours creating the most risk.
Human Risk Management is not about catching people out. It is about giving them enough realistic practice that the safer action becomes the normal action.
Phishing simulation + awareness training + reinforcement + measurable improvement.
Why Human Risk Matters
Technology filters threats.
People still make decisions.

Email security, endpoint protection and identity controls stop a large amount of malicious activity before a user ever sees it. But phishing, impersonation, credential theft and social engineering are deliberately designed to influence the decisions people make when something reaches them.

A mature awareness programme therefore does more than assign training once a year. It creates a cycle of realistic testing, relevant learning, reinforcement and measurement so the organisation can see whether user behaviour is actually improving.

The goal is not a perfect simulation score. The goal is fewer risky actions and faster reporting when a real attack arrives.

The Human Risk Cycle

Make awareness an operating process, not an annual event.

01 / BASELINE

Understand current risk

Run an initial simulation to establish how users recognise, interact with and report suspicious messages.

02 / SIMULATE

Test realistic behaviour

Run ongoing phishing simulations using scenarios relevant to modern email and social-engineering attacks.

03 / TRAIN

Teach what matters

Deliver concise awareness training covering the risks users are most likely to encounter in their role and environment.

04 / REINFORCE

Follow up intelligently

Use immediate feedback, targeted training and repeat campaigns to improve behaviour without creating training fatigue.

05 / MEASURE

Track improvement

Monitor trends by user, group or organisation and focus future activity on the areas creating the greatest human risk.

Two Supported Platforms

Choose the model that fits your environment.

Vectra supports both KnowBe4 and Check Point Email Security. They solve the same core problem in different ways: one is a dedicated Human Risk Management platform; the other brings phishing simulation and awareness training directly into the email-security platform.

KnowBe4
Dedicated Human Risk Platform

Maximum depth, flexibility and customisation.

KnowBe4 is the stronger fit when security awareness is a dedicated programme in its own right. Its current AI-Native Security Awareness Training combines training, phishing and vishing simulation, real-time coaching, user risk scoring and extensive analytics inside a standalone platform.

  • Large, continually updated awareness-training library
  • Training content available across 35+ languages
  • Phishing and vishing simulations
  • Custom campaigns, templates and user groups
  • Role- and risk-based personalisation
  • Real-time coaching and targeted follow-up
  • User, group and organisational risk scoring
  • Extensive reporting and executive dashboards
  • Directory and user-provisioning integrations
Best fit Organisations wanting a dedicated, highly configurable awareness programme with deeper content, automation, analytics and human-risk functionality.
Check Point Email Security
Integrated SAT Add-On

Awareness built into the email-security stack.

For organisations already using Check Point Email Security, Security Awareness Training can be added directly to the existing platform. This simplifies deployment, user targeting and reporting while keeping phishing testing close to the email controls protecting the organisation.

  • Microsoft 365 and Google Workspace support
  • Phishing simulations delivered directly to user mailboxes via API
  • No simulation sending-IP allowlisting required
  • AI-adaptive phishing simulations based on recent attack patterns
  • Custom administrator-created phishing templates
  • Security awareness training modules and reminders
  • User and group targeting through SAT policies
  • Simulation, feedback and training activity visible in Email Security
  • Single operational platform alongside email protection
Best fit Check Point Email Security customers wanting straightforward phishing simulation and awareness training without deploying another standalone security platform.
Which Platform?

There is no need to force one answer on every customer.

Both platforms can deliver a strong security-awareness programme. The choice is mainly about how much depth you need and whether consolidation into the email-security platform is valuable.

Already using Check Point Email SecurityKeep user testing, training and reporting close to the email platform and reduce deployment overhead.Check Point
Dedicated enterprise awareness programmeUse a standalone platform with deeper customisation, content, risk scoring, automation and programme controls.KnowBe4
Complex groups or business unitsBuild more granular campaigns, different training journeys and advanced reporting across varied user populations.KnowBe4
Fast deploymentFor existing Check Point customers, enable SAT within the same platform and avoid traditional phishing-simulation delivery issues.Check Point
Extensive training libraryUse broader standalone content and ongoing personalisation across roles, risks and languages.KnowBe4
Simple phishing + awareness requirementUse the integrated SAT capability where the organisation wants strong core functionality without another management console.Check Point
Managed by Vectra

We can run the programme, not just sell the licence.

Vectra can manage the ongoing Human Risk Management programme on either supported platform. That includes campaign planning, user management, phishing simulation, training assignment, reporting and continuous improvement.

Customers can also operate the platform internally, or use a co-managed model where Vectra handles the technical and campaign administration while internal teams own communications and culture.

01
ONBOARDConfigure the platform, user synchronisation, domains, policy, branding and required simulation-delivery settings.
02
BASELINEEstablish the starting point with an initial simulation and review current training or policy requirements.
03
CAMPAIGNSchedule randomised phishing simulations and recurring awareness activity without making the programme predictable.
04
REMEDIATEAssign targeted follow-up or additional learning where users or groups demonstrate repeated risky behaviour.
05
REPORTProvide clear management reporting covering simulation outcomes, reporting behaviour, completion and risk trends.
06
IMPROVEAdjust scenarios, training content and cadence based on actual outcomes and emerging social-engineering techniques.
Typical Managed Cadence

Frequent enough to change behaviour. Not so frequent that people tune out.

The exact programme is tailored to the organisation, but a practical managed service can use the following structure.

Onboarding

Baseline & induction

Initial phishing simulation, mandatory foundation training and onboarding awareness for new employees.

Monthly

Random phishing simulations

Ongoing unannounced simulations spread across the user population so testing becomes part of normal security behaviour.

Quarterly

Awareness training

Short, relevant learning aligned to current risks, policy requirements and lessons from recent simulation outcomes.

Ongoing

Targeted reinforcement

Additional coaching, remedial training or focused simulations for teams or users showing higher-risk behaviour.

What We Train & Test

Focus on the decisions attackers actually try to influence.

Phishing

Links and credential theft

Recognise suspicious messages, unsafe links, fake login pages and attempts to capture usernames, passwords or MFA details.

Impersonation

BEC and executive fraud

Identify urgent payment requests, supplier impersonation, executive spoofing and attempts to bypass normal approval processes.

QR & Modern Lures

Quishing and mobile handoff

Build awareness of QR-code attacks and messages designed to shift users from protected corporate devices into less visible channels.

Social Engineering

Trust and urgency

Recognise manipulation techniques based on authority, fear, curiosity, urgency and familiarity.

Identity

Passwords and MFA

Reinforce secure authentication behaviour, password hygiene, MFA prompts and the need to report unexpected access attempts.

Data Handling

Safer everyday decisions

Support awareness around sensitive information, cloud sharing, collaboration tools and organisational security policies.

Measure Behaviour, Not Attendance

Training completion is only one metric.

A user completing an awareness module does not automatically mean risk has changed. Vectra uses the reporting available in the selected platform to look at behaviour over time and identify where additional focus is required.

Simulation interactionWho clicked, replied, entered data or otherwise interacted with a simulated attack.
Reporting behaviourWhether users recognised and reported suspicious messages rather than simply ignoring them.
Repeat behaviourIdentify recurring risky actions and teams that may need different training or scenarios.
Training completionTrack assigned modules, completion status and outstanding awareness requirements.
Risk trendsMeasure improvement over time using the scoring and analytics available in the chosen platform.
Management reportingGive security and leadership a clear view of programme participation, human risk and improvement priorities.
Flexible Engagement

Platform only, fully managed, or somewhere in between.

Platform

Your team runs it

Vectra helps select, procure and deploy KnowBe4 or Check Point SAT, then hands day-to-day campaign management to your internal security or IT team.

Co-Managed

Share the workload

Vectra manages configuration, campaigns and reporting while your internal team owns user communications, policy and organisational change.

Managed

Vectra runs the programme

Vectra handles onboarding, recurring simulations, training campaigns, reporting and ongoing improvement as an operational service.

Human Risk Management FAQs

Choosing and running the right programme.

What is Human Risk Management?

Human Risk Management is the ongoing process of identifying, reducing and measuring cyber risk created by user behaviour. In this service, the focus is phishing simulation, security awareness training, reinforcement and reporting rather than relying on a once-a-year training exercise.

Does Vectra support KnowBe4?

Yes. Vectra is a KnowBe4 partner and can provide procurement, implementation, campaign design, reporting and fully managed or co-managed security-awareness programmes.

Does Check Point Email Security include phishing simulation?

Check Point Email Security offers Security Awareness Training as an additional capability. It supports phishing simulations, awareness-training policies and reporting for Microsoft 365 and Google Workspace environments.

What is the advantage of Check Point Security Awareness Training?

For an existing Check Point Email Security customer, the main advantage is integration. Phishing simulations can be inserted directly into supported user mailboxes via API, avoiding traditional simulation-delivery allowlisting, while training, targeting and reporting remain close to the existing email-security platform.

Why would we choose KnowBe4 instead?

KnowBe4 is a dedicated Human Risk Management and security-awareness platform. It is generally the stronger fit where an organisation wants deeper customisation, a larger content library, broader simulation options, risk scoring, real-time coaching and more sophisticated programme automation and analytics.

How often should phishing simulations be run?

Frequency should be high enough to reinforce behaviour without making testing predictable or creating user fatigue. A common managed approach is randomised monthly simulation activity with periodic awareness training and additional targeted follow-up where needed.

Should users be told that phishing simulations are running?

Organisations should communicate that phishing simulations form part of the security-awareness programme, but they generally do not need to announce the timing or content of individual tests. Internal HR, privacy, legal or industrial requirements should be considered when defining the programme.

Can Vectra manage the whole programme?

Yes. Vectra can manage platform configuration, user synchronisation, recurring phishing campaigns, training assignment, targeted remediation, reporting and ongoing programme improvement on either supported platform.

Human Risk Management

Give people the practice to make better security decisions.

Talk to Vectra about KnowBe4, Check Point Security Awareness Training, phishing simulations or a fully managed Human Risk Management programme.

Build a Human Risk Program →
Platform capabilities vary by product edition, licensing and release. Vectra will confirm the appropriate KnowBe4 or Check Point configuration during scoping. Phishing simulations should be operated within the organisation’s applicable HR, privacy, legal and security policies.